URLhaus Database

You are currently viewing the URLhaus database entry for https://itstoreindia.com/ico/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2646320
URL: https://itstoreindia.com/ico/?1
URL Status:Offline
Host: itstoreindia.com
Date added:2023-05-30 16:50:43 UTC
Last online:2023-05-31 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-30 16:52:22 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 6 hours, 22 minutes Poor (down since 2023-05-31 23:14:30 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_E673_May_31.zipzip cedf0af618e0314198c5c6d1f3165b993aaa3bd8c40d6f821cc0f6c2b3b8099aVirustotal results 23.33% Quakbot
2023-05-31doc_C706_May_31.zipzip 9a5a1611eaa87d1c626bbe13b8196b83dc23b956bee9d48650c879a61c19938dVirustotal results 19.35% Quakbot
2023-05-31doc_C983_May_31.zipzip 447045e3ce5008aeaa4fe18c4afff9aab822795d94a367308151e2989c04a778Virustotal results 19.67% Quakbot
2023-05-31doc_F804_May_31.zipzip d2dc2ba9a8421136a180210ce506ce9ec623673580d3959b7da52b34919e34c2Virustotal results 22.58% Quakbot
2023-05-31doc_F249_May_31.zipzip 0f78f2db5e8b2c32b47661ee56ae475fa4ac696be359cdf55592ebbc87921a99n/a Quakbot
2023-05-31doc_E185_May_30.zipzip 44d7e0b94ef9f36cbbd6096c1354eee4c2c61540911ebea292b17d1d636c94cbVirustotal results 19.35% Quakbot
2023-05-31doc_F763_May_30.zipzip f1cc9f86c17f7afd0a8b7f1eb8b25e59fed91690cf5bebfc763ed9ee2a411b8fVirustotal results 19.35% Quakbot
2023-05-31doc_A851_May_30.zipzip 9777a21e3a2c22d2ae2ff8a572cb426bbd4f991b7a22821a18bfc3e4ee0e2deeVirustotal results 19.35% Quakbot
2023-05-31doc_D345_May_30.zipzip 718dbe354fc126eeb08be2005ce01022d37a65f8d40e7dee50387c65ce0dbe83Virustotal results 19.35% Quakbot
2023-05-31doc_C165_May_30.zipzip 791f1031845a3fa07f2450a21520113b5345ff2f299b351f760102976e6d57a9Virustotal results 20.00% Quakbot
2023-05-31doc_D836_May_30.zipzip 73f7ea2fe703e8399d0e53d74d5eec69eb343771524acef52ef6be4efd936289Virustotal results 18.03% Quakbot
2023-05-31doc_A615_May_30.zipzip cf4b07d31f0a05d76600aae08637c1942052dc84af85d28b1d6bf44ed8b1d523Virustotal results 19.35% Quakbot
2023-05-30doc_A412_May_30.zipzip 8c0538089a97c041dce5df07b6b5c8518333e5a991b4dc05160c57968970e8d1Virustotal results 19.67% Quakbot
2023-05-30doc_B869_May_30.zipzip 785ee460f71ec051a367cd3ada18c1d0b1854d361216cec628c9f366aaf24f24Virustotal results 17.74% Quakbot
2023-05-30doc_A492_May_30.zipzip 5687f0fae2a937ee9ac6bb2601ff1558b50b4785ec36849bf99bad96c0109c4bVirustotal results 17.74% Quakbot
2023-05-30doc_B048_May_30.zipzip ac093215c7cae84e5a0e99186a8038f0526839f1fd1a8564d78c00f2182e1796Virustotal results 18.03% Quakbot
2023-05-30doc_D756_May_30.zipzip cc166441b04dcb62c6cc534ad3dc470292df30e416df52eedaeb1f60e0dd6692n/a Quakbot